|
265421
|
7.5 |
HIGH
Network
|
f5
|
big-ip_edge_gateway big-ip_protocol_security_module big-ip_analytics big-ip_application_security_manager big-ip_advanced_firewall_manager big-ip_domain_name_system big-ip_policy_enf…
|
Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote att…
|
CWE-284
Improper Access Control
|
CVE-2016-5023
|
2024-11-21 11:53 |
2016-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265422
|
9.8 |
CRITICAL
Network
|
zmodo
|
zp-ibh-13w zp-ne-14-s
|
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-5081
|
2024-11-21 11:53 |
2016-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265423
|
5.3 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtai…
|
CWE-200
Information Exposure
|
CVE-2016-4995
|
2024-11-21 11:53 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265424
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-5146
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265425
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, …
|
CWE-254
7PK - Security Features
|
CVE-2016-5145
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265426
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which…
|
CWE-284
Improper Access Control
|
CVE-2016-5144
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265427
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5143
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265428
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial o…
|
CWE-416
Use After Free
|
CVE-2016-5142
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265429
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.…
|
CWE-20
Improper Input Validation
|
CVE-2016-5141
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265430
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5140
|
2024-11-21 11:53 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|